With the development of the information society, we are surrounded by various threats such as computer viruses, leakage of personal information, and unauthorized access from the outside. Against diversifying threats, efforts for security measures are one of the most important issues for customers. These security threats are not limited to personal computers, servers, and networks. You can reduce such security threats by regarding a multifunction printers as one of the IT devices and setting and operating it appropriately.
Ricoh updates software/firmware and provides security patches to fix vulnerabilities detected in its products such as multifunction printers and printers. In order to use the multifunction printers and printers more safely, please use the latest software/firmware of the products.
By placing your information devices, including multifunction printers and printers, in a network isolated by a firewall, you can prevent unauthorized access from the Internet.
PC operation
Operate machines with private IP address.
Unauthorized access from the Internet can be prevented by operating machines in a local area network environment such as an inhouse LAN.
By changing the administrator password/supervisor password of machine, you can prevent the attacks (setting changes) by a malicious third party from the Internet. Be sure to change the password from the default value.
We recommend you protect the data stored on multifunction printers by using the user authentication or the password for documents stored in document server settings.
・By performing user authentication such as the user identification or authentication (IC card or password input), only authorized users can use multifunction printers.
・By setting the password for documents stored in document server, any third party cannot use the machines by setting a password for accessing the documents stored in document server.
SMB settings (*2)
Storage encryption
Access privilege setting
We recommend you limit the permissions to cancel a job to the job owner and the administrator.
Access limitation by IP address
We recommend you limit the range of IP addresses of PCs that can use MFPs/printers as much as possible. You can prevent unauthorized access from the Internet.
Closing unused communication port (*3) (*4)
SSL/TLS settings
IPsec settings
SNMP settings
(*1) When you change the machine settings, it may affect the application in use, so check the settings and operation of the application before you change the settings.
(*2) If you use SMB3.0, you will not be able to use the Windows authentication.
(*3) Since PC FAX acquires the transmission result via FTP, you can no longer acquire the transmission result by closing the FTP port.
(*4) UnixFilter prints through lpr/lp/qprt, so if you close lpr/ lp /qprt, printing will no longer be performed.
(*5) The Job Deletion Tool of Enhanced Locked Print NX V2 will no longer be available.
(*6) RC Gate: Remote Communication Gate will no longer be available.
We also support various security functions, so please use them according to your environment. For details of the security functions, see the website below.
https://www.ricoh.com/products/security/mfp/function/
An IP address is a number assigned to a machine on the network. The IP address used to connect to the Internet is called the "global IP address", while the IP address assigned to a machine used in the local area network such as an inhouse LAN is called the "private IP address".
If a global IP address is set for a multifunction printers, it will be accessible to an unspecified number of users on the Internet, increasing the risk of information leakage due to unauthorized access from the outside. On the other hand, if a private IP address is set for a multifunction printers, it can only be accessed by users on the local area network such as an inhouse LAN. Basically, we recommend you set a private IP address for the IP address of a multifunction printers. For a private IP address, one in the following range is used.
[Private IP address range]
10.0.0.0 to 10.255.255.255
172.16.0.0 to 172.31.255.255
192.168.0.0 to 192.168.255.255
*Please do not forget the login user name and login password for supervisor.
<For products which do not display password entry screen at startup>
Press [Settings] ⇒ [Administrator Tools] ⇒ [Administrator Authentication Management] ⇒ [Program/Change Administrator] on the operation panel and specify the setting
For details about administrator authentication, refer to the descriptions for "Security" in guide.
<For products which displays password entry screen at startup>
(For RICOH IM C6000/C5500/C4500/C3500/C3000/C2500/C2000)
(For more details, see the website)
(For RICOH IM C6000/C5500/C4500/C3500/C3000/C2500/C2000)
(For more details, see the website)
The flow of user authentication setting is as follows.
*Also user authentication can be performed by using IC card authentication system. For details, contact your service representative.
(For RICOH IM C6000/C5500/C4500/C3500/C3000/C2500/C2000)
The document administrator or the document owner can specify the password
On the Home screen, press [Document Server]. -> select the desired folder -> select the document to specify the password -> press [Change File Info.] (*).
(*) The procedure differs depending on model type.
You can use 4 - 8 digits numbers in the document password. For more details about preventing information leakage and specifying the password for documents stored in document server, refer to the descriptions for "Security" in guide.
(For RICOH IM C6000/C5500/C4500/C3500/C3000/C2500/C2000)
The document administrator or the document owner can specify the password
Log out.
*You can also specify this setting by using Web Image Monitor of the PC
(For more details, see the website)
(For more details, see the website)
Select either of user authentication method: User code authentication, Basic authentication, Windows authentication, LDAP authentication, Integration server authentication beforehand.
*User code authentication/Integration server authentication may not available in some models.
(For RICOH IM C6000/C5500/C4500/C3500/C3000/C2500/C2000)
(For more details, see the website)
You can specify the range of device's IP address that can access to the machine from the PC.
(For RICOH IM C6000/C5500/C4500/C3500/C3000/C2500/C2000)
(For more details, see the website)
You can specify the range of device's IP address that can access to the machine from the PC.
(For RICOH IM C6000/C5500/C4500/C3500/C3000/C2500/C2000)
(For more details, see the website)
You can install a device certificate from your PC via the Web.
You can specify encryption settings for network communication from your PC via the Web.
You can specify the level for encryption setting from Web Image Monitor of the PC.
(For more details, see the website)
Activate IPsec.
*Select Inactive in Exclude HTTPS Communication so that even if the IPsec settings are incorrect, the settings can be changed via the Web. In such case, communication security can be maintained with SSL.
*When IPsec settings are wrong, you can specify the settings again by selecting Inactive to IPsec on the operation panel.
Community setting
Security strengths can be improved by not sharing Community Names among large numbers of people, such as by separating Community Names for each business site.
Encrypting Data Communicated with Machine Management Software via SNMPv3